Sceawere

Vulnerability Detail

CVE-2026-79679UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Weak Credential Vulnerability in mapp Audit

Vulnerability Metadata

Severity
High
Score / CVSS
8.7
Creation Date
4h ago
Vendor
B&R Industrial Automation GmbH
Product
mapp Services
Attack Type
CWE-1391 Use of Weak Credentials
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services. This issue affects mapp Audit used in mapp Services: before 6.8.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.7",
  "pubDate": "2026-09-03T13:06:10.430Z",
  "pubdate": "2026-09-03T13:06:10.430Z",
  "executiveSummary": "This vulnerability involves the Use of Weak Credentials within the B&R Industrial Automation GmbH mapp Audit component, integrated into mapp Services.\nThe identified flaw allows unauthorized entities to potentially bypass authentication mechanisms or gain elevated access to the auditing functions of the affected systems.\nThe vulnerability affects all versions of mapp Audit used in mapp Services prior to 6.8.0.\nThe risk implication is significant for industrial environments, as unauthorized access to audit logs and system configuration audit trails can lead to the manipulation or concealment of malicious activities.\nThe attacker requires network access to the target service to exploit this vulnerability. No sophisticated authentication tokens are required if the system relies solely on the default or weak credential implementations.\nSuccessful exploitation compromises the integrity and confidentiality of the industrial automation auditing process, potentially allowing an attacker to operate without detection by modifying audit trails.",
  "technicalDetails": "The root cause of the vulnerability lies in the implementation of insufficient complexity or hardcoded password policies within the authentication modules of mapp Audit. By utilizing weak, easily guessable, or default credentials for service access, the component fails to enforce adequate identity verification, rendering it susceptible to unauthorized access.\nThe vulnerable component is identified as the authentication logic within mapp Audit, a core service responsible for logging and tracking operational events in B&R Industrial Automation systems.\nThe exploitation flow begins with the attacker identifying the network-reachable mapp Services instance. Upon connection, the attacker leverages the known weak credential weakness to authenticate against the system. Because the credentials lack sufficient entropy or follow predictable patterns, automated brute-force or dictionary attacks can be performed with minimal effort to bypass access controls.\nOnce authenticated, the attacker gains the privileges associated with the account, which in many cases includes read/write access to audit logs or the ability to configure auditing parameters. The post-exploitation behavior involves the manipulation of sensitive log data, potentially deleting records of unauthorized system changes or inserting false entries to obfuscate subsequent malicious actions within the industrial controller environment.\nThis issue is present in all iterations of the software prior to version 6.8.0. The vulnerability is exploitable via the network protocols utilized by mapp Services to interface with external clients or HMI (Human-Machine Interface) systems. There are no secondary authentication requirements once the primary weak credential barrier is breached, allowing for direct interaction with the underlying auditing framework.\nThe technical impact includes a total loss of trust in the integrity of the audit logs, which is a critical failure in industrial safety and compliance environments. By compromising the auditing layer, the attacker can effectively 'blind' security monitoring systems, ensuring their presence remains undetected during the lifecycle of an incident."
}
CVE-2026-79679: Weak Credential Vulnerability in mapp Audit (HIGH Severity, CVSS: 8.7) - Sceawere